Skip to content

Lexoh Security and Maintenance Checklist

Review permissions, network settings, maintenance and recovery responsibilities with the team operating your Lexoh installation.

Start with security practices

Best Practices

Use this operational checklist with your system administrator and installer. Confirm which controls the deployed version supports, assign an owner to each task and agree on acceptance evidence. These planning practices do not establish a product certification or a recovery guarantee.

Security

Access Control

  • Principle of Least Privilege: Grant users minimum necessary permissions
  • Access reviews: Review permissions when roles change or users leave, and on the schedule agreed by the organization.
  • Administrative authentication: Use the supported multi-factor authentication method for privileged accounts; confirm enrollment and recovery with the system owner.
  • Passwords: Use unique passwords and change them when compromise is suspected or confirmed. Do not impose arbitrary periodic changes as a substitute for effective authentication.
  • Role-Based Access: Use groups instead of individual permissions

Reference: NIST authentication and password guidance

Network Security

  • Segmentation: Isolate IoT devices on separate VLAN
  • Firewall Rules: Allow only required ports and protocols
  • VPN Access: Use VPN for remote administration
  • Certificates: Validate trusted certificates and plan renewal. Do not bypass certificate errors to restore connectivity.
  • Vulnerability review: Schedule authorized assessments with the system owner, taking account of operational equipment and maintenance windows.

Data Protection

  • Stored data: Confirm supported encryption, key ownership and administrator access for each storage service and backup.
  • Data in transit: Use authenticated, encrypted connections supported by the approved architecture; document any legacy device limitations.
  • Session Management: Protect session tokens and end sessions that are no longer needed
  • Retention: Apply the organization’s approved retention and deletion policy to video, access events and exported records.
  • Secure Backups: Encrypt backups and store offsite
Critical: Keep passwords and session tokens out of email, chat and version control. Store them in protected application configuration or a secrets manager.

Network Architecture

Illustrative network segmentation

Internet → firewall/router → separate network segments. The VLAN identifiers and subnets below are examples for the network design.

VLAN 10 · Management
192.168.10.0/24
Administrator workstations and servers
VLAN 20 · Access control
192.168.20.0/24
Card readers and door controllers
VLAN 30 · Cameras
192.168.30.0/24
IP cameras and network video recorder
VLAN 40 · Parking
192.168.40.0/24
Barriers, kiosks and sensors

Bandwidth Planning

Device Type What to measure What affects the result
Access Control Access events, synchronization and firmware transfers Event volume, update size and simultaneous devices
1080p Camera Configured stream bitrate and simultaneous viewers Codec, frame rate, scene motion and recording profile
4K Camera Configured streams, playback and exports Image settings, analytics needs and concurrent use
Parking System Lane events, payment services and remote assistance Lane count, service interfaces and any audio/video
Access Control
What to measure:

Access events, synchronization and firmware transfers

What affects the result:

Event volume, update size and simultaneous devices

1080p Camera
What to measure:

Configured stream bitrate and simultaneous viewers

What affects the result:

Codec, frame rate, scene motion and recording profile

4K Camera
What to measure:

Configured streams, playback and exports

What affects the result:

Image settings, analytics needs and concurrent use

Parking System
What to measure:

Lane events, payment services and remote assistance

What affects the result:

Lane count, service interfaces and any audio/video

Sizing method: Measure simultaneous traffic for the configured devices and video streams, then include playback, exports, updates and the headroom agreed with IT. Resolution or device count alone does not establish bandwidth.

Performance Optimization

Camera Optimization

  • Bitrate: Choose a supported encoding profile and verify image detail and measured storage use in the actual scene.
  • Frame rate: Select the rate required by the observation or analytics task and test moving subjects.
  • Keyframe interval: Use a setting supported by the camera and recording system, then verify playback and seeking.
  • Region of Interest: Higher quality for important areas
  • Night operation: Verify exposure, lighting and any supported day/night settings in the installed view.

Data lifecycle and administration

  • Archiving: Define which records must remain available and verify retrieval before changing storage.
  • Managed services: Refer database tuning to the responsible service administrator; do not modify an application schema without a supported change plan.
  • Capacity: Monitor record growth, query performance and backup duration against the agreed operating needs.
  • Deletion: Apply authorized deletion through supported tools and account for exports and backups.

API Usage

  • Supported operations: Use the documented endpoints; combine operations only when a batch endpoint is explicitly supported.
  • Caching: Set refresh and invalidation rules according to the data’s use; stale permissions must not drive an access decision.
  • Pagination: Follow the selected endpoint’s documented parameters and limits, and test completion across multiple pages.
  • Event Retrieval: Paginate event history and track processed event identifiers
  • Request Volume: Bound concurrent requests and pause before retrying transient failures

Maintenance Procedures

Example maintenance schedule to agree with your team

Frequency Tasks
Daily • Check device online status
• Review critical alerts
• Verify backup completion
Weekly • Test access credentials
• Review access logs for anomalies
• Check storage capacity
• Test video playback
Monthly • Inspect and clean equipment as specified by its manufacturer
• Review supported updates before scheduling installation
• Inspect power backup and storage
• Review access permissions
Quarterly • Review the operating and security plan
• Schedule authorized recovery exercises
• Update records and operator training
• Reconcile open defects and service responsibilities
Daily
Tasks:

• Check device online status
• Review critical alerts
• Verify backup completion

Weekly
Tasks:

• Test access credentials
• Review access logs for anomalies
• Check storage capacity
• Test video playback

Monthly
Tasks:

• Inspect and clean equipment as specified by its manufacturer
• Review supported updates before scheduling installation
• Inspect power backup and storage
• Review access permissions

Quarterly
Tasks:

• Review the operating and security plan
• Schedule authorized recovery exercises
• Update records and operator training
• Reconcile open defects and service responsibilities

Change Management

  1. Document all changes before implementation
  2. Test changes in staging environment first
  3. Schedule maintenance windows during low-traffic periods
  4. Agree on the notification period and obtain the affected operator’s approval.
  5. Keep rollback plan ready
  6. Monitor the agreed functions after the change and record acceptance or unresolved defects.

Disaster Recovery

Backup Strategy (3-2-1 Rule)

  • 3 Copies: Production data + 2 backups
  • Separate storage: Keep backup copies on independent storage arrangements agreed with IT.
  • Offsite copy: Confirm the responsible service, covered data, backup schedule and restore procedure. Cloud hosting alone does not prove backup coverage.

Recovery Time Objectives (RTO)

  • Recovery time: Agree the maximum acceptable interruption for each service and the operational fallback.
  • Recovery point: Define the acceptable data-loss window and compare it with the backup and replication arrangements.
  • Evidence: Test restoration using an approved exercise, record actual results and resolve gaps. Targets must be confirmed in the service agreement.

Emergency Contacts

Maintain an updated emergency contact list:

  • LEXOH Support: support@lexoh.com
  • Network Administrator
  • Security Manager
  • Facility Manager
  • Key vendors and contractors

Compliance & Standards

Frameworks to review when applicable; no certification claim

  • ISO 27001: Information security management
  • GDPR: Data protection (EU)
  • CCPA: Consumer privacy (California)
  • HIPAA: Healthcare data (if applicable)
  • PCI DSS: Payment card security

Documentation Requirements

  • Network diagrams updated after approved changes
  • User access matrix
  • Incident response plan
  • Privacy policy and data handling procedures
  • Change log and audit trail

First operational checks

Start with these checks and assign any configuration changes to the authorized owner:

  • Confirm supported multi-factor authentication for administrator access.
  • Verify the backup scope and a recent successful restoration test.
  • Test the configured critical alerts and the person responsible for responding.
  • Review and remove inactive users
  • Review supported firmware versions and plan updates through change control.
  • Check camera views and any configured detection rules against the intended task.
  • Plan an authorized recovery exercise with the affected site operator.
  • Document your network topology

Need Help?

Check our troubleshooting guide for common issues and solutions

Troubleshooting Guide →
Call Lexoh 1-888-401-8019